panews-creator

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests article content from local Markdown and HTML files to facilitate publishing and revision workflows. This creates a surface where malicious instructions embedded in those files could influence the agent's behavior during polishing or review steps.
  • Ingestion points: Article content is read via the --content-file argument in references/workflow-publish.md and references/workflow-revise.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore potential commands embedded within the article content.
  • Capability inventory: The skill has the capability to execute shell commands via a local Node.js CLI and interact with the PANews platform via network requests.
  • Sanitization: No explicit content validation or sanitization process is described for the ingested file content.
  • [COMMAND_EXECUTION]: The skill relies on executing a local Node.js script (scripts/cli.mjs) to perform all creator actions, including session validation, article status management, and image uploads. While this is standard for the skill's purpose, it involves the execution of shell commands based on parameters derived from user input and article metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 02:29 AM
Security Audit — agent-trust-hub — panews-creator